[Git][security-tracker-team/security-tracker][master] 2 commits: libxmltok/LTS

Bastien Roucariès (@rouca) rouca at debian.org
Wed Aug 5 19:38:04 BST 2026



Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker


Commits:
de38be23 by Bastien Roucariès at 2026-08-05T20:37:10+02:00
libxmltok/LTS

- - - - -
2c7564cc by Bastien Roucariès at 2026-08-05T20:37:35+02:00
Remove libxmltok from dla-needed

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -232417,6 +232417,7 @@ CVE-2024-8176 (A stack overflow vulnerability exists in the libexpat library due
 	[bullseye] - expat <ignored> (Minor issue and too intrusive to backport)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://blog.hartwork.org/posts/expat-2-7-0-released/
 	NOTE: https://github.com/libexpat/libexpat/issues/893
 	NOTE: https://github.com/libexpat/libexpat/pull/973
@@ -275894,6 +275895,7 @@ CVE-2024-50602 (An issue was discovered in libexpat before 2.6.4. There is a cra
 	[bookworm] - expat 2.5.0-1+deb12u2
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/915
 	NOTE: https://github.com/libexpat/libexpat/commit/51c7019069b862e88d94ed228659e70bddd5de09 (R_2_6_4)
 	NOTE: https://github.com/libexpat/libexpat/commit/5fb89e7b3afa1c314b34834fe729cd063f65a4d4 (R_2_6_4)
@@ -289923,6 +289925,7 @@ CVE-2024-45492 (An issue was discovered in libexpat before 2.6.3. nextScaffoldPa
 	- expat 2.6.2-2 (bug #1080152)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/892
 	NOTE: https://github.com/libexpat/libexpat/issues/889
 	NOTE: https://github.com/libexpat/libexpat/commit/29ef43a0bab633b41e71dd6d900fff5f6b3ad5e4 (R_2_6_3)
@@ -289931,6 +289934,7 @@ CVE-2024-45491 (An issue was discovered in libexpat before 2.6.3. dtdCopy in xml
 	- expat 2.6.2-2 (bug #1080150)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/891
 	NOTE: https://github.com/libexpat/libexpat/issues/888
 	NOTE: https://github.com/libexpat/libexpat/commit/b8a7dca4670973347892cfc452b24d9001dcd6f5 (R_2_6_3)
@@ -289939,6 +289943,7 @@ CVE-2024-45490 (An issue was discovered in libexpat before 2.6.3. xmlparse.c doe
 	- expat 2.6.2-2 (bug #1080149)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/890
 	NOTE: https://github.com/libexpat/libexpat/issues/887
 	NOTE: https://github.com/libexpat/libexpat/commit/e5d6bf015ee531df0a8751baa618d25b2de73a7c (R_2_6_3)
@@ -342735,6 +342740,7 @@ CVE-2024-28757 (libexpat through 2.6.1 allows an XML Entity Expansion attack whe
 	- expat 2.6.1-2 (bug #1065868; unimportant)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/842
 	NOTE: https://github.com/libexpat/libexpat/issues/839
 	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/1d50b80cf31de87750103656f6eb693746854aa8
@@ -351557,6 +351563,7 @@ CVE-2023-52426 (libexpat through 2.5.0 allows recursive XML Entity Expansion if
 	- expat 2.6.0-1 (bug #1063240; unimportant)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/777
 	NOTE: https://github.com/libexpat/libexpat/commit/0f075ec8ecb5e43f8fdca5182f8cca4703da0404
 	NOTE: https://github.com/libexpat/libexpat/pull/777#issuecomment-1965172301
@@ -351568,6 +351575,7 @@ CVE-2023-52425 (libexpat through 2.5.0 allows a denial of service (resource cons
 	[bookworm] - expat 2.5.0-1+deb12u2
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/789
 	NOTE: Merge commit: https://github.com/libexpat/libexpat/commit/34b598c5f594b015c513c73f06e7ced3323edbf1
 CVE-2020-36773 (Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-a ...)
@@ -439698,6 +439706,7 @@ CVE-2022-43680 (In libexpat through 2.4.9, there is a use-after free caused by o
 	- expat 2.5.0-1 (bug #1022743)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/issues/649
 	NOTE: https://github.com/libexpat/libexpat/pull/616
 	NOTE: https://github.com/libexpat/libexpat/pull/650
@@ -448210,6 +448219,7 @@ CVE-2022-40674 (libexpat before 2.4.9 has a use-after-free in the doContent func
 	- expat 2.4.8-2 (bug #1019761)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/629
 	NOTE: https://github.com/libexpat/libexpat/pull/640
 	NOTE: https://github.com/libexpat/libexpat/commit/4a32da87e931ba54393d465bb77c40b5c33d343b
@@ -491841,6 +491851,7 @@ CVE-2022-25315 (In Expat (aka libexpat) before 2.4.5, there is an integer overfl
 	- expat 2.4.5-1
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/559
 	NOTE: https://github.com/libexpat/libexpat/commit/eb0362808b4f9f1e2345a0cf203b8cc196d776d9
 CVE-2022-25314 (In Expat (aka libexpat) before 2.4.5, there is an integer overflow in  ...)
@@ -491848,6 +491859,7 @@ CVE-2022-25314 (In Expat (aka libexpat) before 2.4.5, there is an integer overfl
 	- expat 2.4.5-1
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	[stretch] - expat <not-affected> (Vulnerable code introduced later)
 	NOTE: https://github.com/libexpat/libexpat/pull/560
 	NOTE: https://github.com/libexpat/libexpat/commit/efcb347440ade24b9f1054671e6bd05e60b4cafd
@@ -491856,6 +491868,7 @@ CVE-2022-25313 (In Expat (aka libexpat) before 2.4.5, an attacker can trigger st
 	- expat 2.4.5-1
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/558
 	NOTE: https://github.com/libexpat/libexpat/commit/9b4ce651b26557f16103c3a366c91934ecd439ab
 CVE-2022-25311 (A vulnerability has been identified in SINEC NMS (All versions >= V1.0 ...)
@@ -492208,6 +492221,7 @@ CVE-2022-25236 (xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers
 	- expat 2.4.5-1 (bug #1005895)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/561
 	NOTE: https://github.com/libexpat/libexpat/commit/6881a4fc8596307ab9ff2e85e605afa2e413ab71
 	NOTE: https://github.com/libexpat/libexpat/commit/a2fe525e660badd64b6c557c2b1ec26ddc07f6e4
@@ -492222,6 +492236,7 @@ CVE-2022-25235 (xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain
 	- expat 2.4.5-1 (bug #1005894)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/562
 	NOTE: https://github.com/libexpat/libexpat/commit/ee2a5b50e7d1940ba8745715b62ceb9efd3a96da
 	NOTE: https://github.com/libexpat/libexpat/commit/3f0a0cb644438d4d8e3294cd0b1245d0edb0c6c6
@@ -496500,6 +496515,7 @@ CVE-2022-23990 (Expat (aka libexpat) before 2.4.4 has an integer overflow in the
 	- expat 2.4.3-3
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/551
 	NOTE: Introduced with: https://github.com/libexpat/libexpat/commit/cb8a4c756d057b948c1b41e7185dd69ef3ade3fb (R_1_95_4)
 	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/ede41d1e186ed2aba88a06e84cac839b770af3a1 (R_2_4_4)
@@ -497282,6 +497298,7 @@ CVE-2022-23852 (Expat (aka libexpat) before 2.4.4 has a signed integer overflow
 	- expat 2.4.3-2
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/550
 	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/847a645152f5ebc10ac63b74b604d0c1a79fae40 (R_2_4_4)
 	NOTE: Tests: https://github.com/libexpat/libexpat/commit/acf956f14bf79a5e6383a969aaffec98bfbc2e44
@@ -501081,6 +501098,7 @@ CVE-2022-22827 (storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has
 	- expat 2.4.3-1 (bug #1003474)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/539
 	NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e (R_2_4_3)
 CVE-2022-22826 (nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 ha ...)
@@ -501088,6 +501106,7 @@ CVE-2022-22826 (nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.
 	- expat 2.4.3-1 (bug #1003474)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/539
 	NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e (R_2_4_3)
 CVE-2022-22825 (lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integ ...)
@@ -501095,6 +501114,7 @@ CVE-2022-22825 (lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an
 	- expat 2.4.3-1 (bug #1003474)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/539
 	NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e (R_2_4_3)
 CVE-2022-22824 (defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has ...)
@@ -501102,6 +501122,7 @@ CVE-2022-22824 (defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4
 	- expat 2.4.3-1 (bug #1003474)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/539
 	NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e (R_2_4_3)
 CVE-2022-22823 (build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an  ...)
@@ -501109,6 +501130,7 @@ CVE-2022-22823 (build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 h
 	- expat 2.4.3-1 (bug #1003474)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/539
 	NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e (R_2_4_3)
 CVE-2022-22822 (addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an i ...)
@@ -501116,6 +501138,7 @@ CVE-2022-22822 (addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 ha
 	- expat 2.4.3-1 (bug #1003474)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/pull/539
 	NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e (R_2_4_3)
 CVE-2022-22821 (NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in wh ...)
@@ -501693,6 +501716,7 @@ CVE-2021-46143 (In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3,
 	- expat 2.4.3-1
 	- libxmltok 1.2-4.2 (bug #1012179)
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/issues/532
 	NOTE: https://github.com/libexpat/libexpat/pull/538
 	NOTE: https://github.com/libexpat/libexpat/commit/85ae9a2d7d0e9358f356b33977b842df8ebaec2b (R_2_4_3)
@@ -503218,6 +503242,7 @@ CVE-2021-45960 (In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or mor
 	- expat 2.4.3-1 (bug #1002994)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://github.com/libexpat/libexpat/issues/531
 	NOTE: https://github.com/libexpat/libexpat/pull/534
 	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/0adcb34c49bee5b19bd29b16a578c510c23597ea (R_2_4_3)
@@ -667774,6 +667799,7 @@ CVE-2019-15903 (In libexpat before 2.2.8, crafted XML input could fool the parse
 	- expat 2.2.7-2 (bug #939394)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	- firefox 70.0-1
 	- firefox-esr 68.2.0esr-1
 	- chromium <not-affected> (uses system libexpat)
@@ -678407,6 +678433,7 @@ CVE-2018-20843 (In libexpat in Expat before 2.2.7, XML input including XML names
 	- expat 2.2.6-2 (bug #931031)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5226
 	NOTE: https://github.com/libexpat/libexpat/issues/186
 	NOTE: https://github.com/libexpat/libexpat/pull/262
@@ -793859,6 +793886,7 @@ CVE-2017-9233 (XML External Entity vulnerability in libexpat 2.2.0 and earlier (
 	- expat 2.2.1-1
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://libexpat.github.io/doc/cve-2017-9233/
 	NOTE: https://github.com/libexpat/libexpat/commit/c4bf96bb51dd2a1b0e185374362ee136fe2c9d7f
 CVE-2017-9232 (Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a ...)
@@ -822244,6 +822272,7 @@ CVE-2016-9063 (An integer overflow during the parsing of XML using the Expat lib
 	- expat 2.2.0-2
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	[jessie] - expat 2.1.0-6+deb8u4
 	[wheezy] - expat <no-dsa> (Minor issue)
 	NOTE: Expat upstream fix: https://github.com/libexpat/libexpat/commit/d4f735b88d9932bd5039df2335eefdd0723dbe20
@@ -834839,6 +834868,7 @@ CVE-2016-5300 (The XML parser in Expat does not use sufficient entropy for hash
 	- expat 2.1.1-3
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 CVE-2016-5244 (The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel t ...)
 	{DSA-3607-1 DLA-516-1}
 	- linux 4.6.2-1
@@ -837614,6 +837644,7 @@ CVE-2016-4472 (The overflow protection in Expat is removed by compilers with cer
 	- expat 2.1.1-2
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: https://sourceforge.net/p/expat/code_git/ci/f0bec73b018caa07d3e75ec8dd967f3785d71bde/tree/expat/lib/xmlparse.c?diff=a238d7ea7a715ef3850c4cbdd86aeda7077b6bbc
 CVE-2016-4471 (ManageIQ in CloudForms before 4.1 allows remote authenticated users to ...)
 	NOT-FOR-US: Red Hat CloudForms
@@ -849968,6 +849999,7 @@ CVE-2016-0718 (Expat allows context-dependent attackers to cause a denial of ser
 	- expat 2.1.1-2
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	- firefox 48.0-1 (unimportant)
 	- firefox-esr <not-affected> (Doesn't affect Firefox ESR)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2016-68/
@@ -852299,6 +852331,7 @@ CVE-2012-6702 (Expat, when used in a parser that has not called XML_SetHashSalt
 	- expat 2.1.1-3
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 CVE-2012-6701 (Integer overflow in fs/aio.c in the Linux kernel before 3.4.1 allows l ...)
 	- linux <not-affected> (Fixed in v3.2.19; which was before src:linux rename)
 	- linux-2.6 3.2.19-1
@@ -873263,6 +873296,7 @@ CVE-2015-1283 (Multiple integer overflows in the XML_GetBuffer function in Expat
 	- expat 2.1.0-7 (bug #793484)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: Patch: https://hg.mozilla.org/releases/mozilla-esr31/rev/2f3e78643f5c
 CVE-2015-1282 (Multiple use-after-free vulnerabilities in fpdfsdk/src/javascript/Docu ...)
 	{DSA-3315-1}
@@ -921317,6 +921351,7 @@ CVE-2013-0340 (expat before version 2.4.0 does not properly handle entities expa
 	- expat 2.4.1-2 (unimportant; bug #1001864)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	NOTE: Expat provides API to mitigate expansion attacks, ultimately under control of the app using Expat
 	NOTE: https://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-0340.html
 	NOTE: Fixed by: https://github.com/libexpat/libexpat/pull/466
@@ -935745,10 +935780,12 @@ CVE-2012-1148 (Memory leak in the poolGrow function in expat/lib/xmlparse.c in e
 	- expat 2.1.0~beta3-1 (bug #663579)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 CVE-2012-1147 (readfilemap.c in expat before 2.1.0 allows context-dependent attackers ...)
 	- expat <not-affected> (readfilemap.c is not used in *IX)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 CVE-2012-1146 (The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in t ...)
 	- linux-2.6 3.2.10-1 (low)
 	[squeeze] - linux-2.6 <not-affected> (Vulnerable code not present)
@@ -936428,6 +936465,7 @@ CVE-2012-0876 (The XML parser (xmlparse.c) in expat before 2.1.0 computes hash v
 	- expat 2.1.0~beta3-1 (bug #663579)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	- xmlrpc-c 1.16.33-3.2 (low; bug #687672)
 	[squeeze] - xmlrpc-c <no-dsa> (Minor issue)
 	- python2.6 <not-affected> (configured with --with-system-expat since 2.6.6-4)
@@ -969202,6 +969240,7 @@ CVE-2009-3720 (The updatePosition function in lib/xmltok_impl.c in libexpat in E
 	- expat 2.0.1-5 (low; bug #551936)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	- mcabber 0.10.0-1 (low; bug #601053)
 	[lenny] - mcabber <no-dsa> (Minor issue)
 	- w3c-libwww <removed> (low; bug #551938)
@@ -969686,6 +969725,7 @@ CVE-2009-3560 (The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0
 	- expat 2.0.1-6 (low; bug #560901)
 	- libxmltok <removed>
 	[bookworm] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
+	[bullseye] - libxmltok <ignored> (Minor issue, no runtime dependencies left)
 	- mcabber 0.10.0-1 (low; bug #601053)
 	[lenny] - mcabber <no-dsa> (Minor issue)
 	- w3c-libwww <removed>


=====================================
data/dla-needed.txt
=====================================
@@ -423,11 +423,6 @@ libwebsockets/bookworm
   NOTE: 20260718: Added by Front-Desk (Beuc)
   NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
 --
-libxmltok
-  NOTE: 20250421: Added by Front-Desk (ta)
-  NOTE: 20250421: Also review all other expat CVEs. (bunk)
-  NOTE: 20250421: Fixing the expat copy in xmlrpc-c at the same time would make sense. (bunk)
---
 libxslt/bullseye
   NOTE: 20250930: Added by Front-Desk (rouca)
   NOTE: 20251020: In progress, waiting for upstream action (guilhem)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c0eb18cb895b2634db0d5574d2e1943fa03a1a6b...2c7564cc129c8c6fa09dc2e20703496e6a07abea

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c0eb18cb895b2634db0d5574d2e1943fa03a1a6b...2c7564cc129c8c6fa09dc2e20703496e6a07abea
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/6ab4cb4e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list